TC-CS-SRCR-Senior_Supply Chain and Third-Party Risk Management
Required skills for this role
PythonAWSAzureServiceNowTableau
About this role
Key Responsibilities
- Lead and independently execute Third Party Security Assessments (TPSA) across critical, high-risk, and strategic vendor portfolios.
- Conduct comprehensive vendor due diligence including control gap analysis, regulatory compliance validation, and risk-tiered scoring.
- Manage the full risk assessment lifecycle — from vendor onboarding due diligence through periodic reviews, escalation management, and exit risk assessments.
- Design and refine vendor risk questionnaires, assessment frameworks, and scoring rubrics aligned to industry standards (ISO 27001, NIST CSF, SOC 2, DORA).
- Perform supply chain risk analysis by identifying nth-party dependencies, concentration risks, and critical vendor failure scenarios.
- Apply AI-enabled vendor risk scoring platforms to prioritize assessments and identify emerging threats.
- Leverage predictive modelling and AI-assisted analytics to forecast vendor risk trajectories and recommend proactive controls.
- Collaborate with procurement, legal, and business stakeholders to embed TPRM controls into vendor contracting and onboarding processes.
- Prepare detailed risk assessment reports, risk ratings, and remediation recommendations for both technical and executive audiences.
- Support the implementation of TPRM automation workflows and AI-driven continuous monitoring capabilities.
- Mentor and guide Staff-level analysts, reviewing work quality and providing technical guidance.
Education / Certifications
- Bachelor’s degree in engineering, Technology, Business, Risk Management, or related disciplines.
- Relevant certifications are advantageous (e.g., ISO 42001, CISSP, CISM, CRISC, ISO 27001 Lead Implementer, CTPRP, or equivalent).
AI & Cyber Certifications
Cyber Security Certifications (Required / Advantageous):
- Certified Information Systems Security Professional (CISSP) – Broad cybersecurity expertise including risk management and third-party security.
- Certified Information Security Manager (CISM) – Information security management and risk governance.
- Certified in Risk and Information Systems Control (CRISC) – IT risk identification, assessment, and lifecycle management.
- Certified Third Party Risk Professional (CTPRP) – Specialized certification in TPRM frameworks and vendor assessment practices.
- ISO/IEC 27001 Lead Implementer – Designing and implementing ISMS controls in vendor assessment contexts.
AI & Data Certifications:
- Microsoft Certified: Azure AI Engineer Associate (AI-102) – Designing and implementing AI solutions relevant to risk automation.
- AWS Certified Machine Learning – Specialty – Understanding ML pipelines applicable to risk scoring models.
- Google Professional Machine Learning Engineer – ML model development and deployment for risk analytics.
- Certified Artificial Intelligence Practitioner (CAIP) – Applied AI concepts across business and risk domains.
- ISACA Certified Data Privacy Solutions Engineer (CDPSE) – Data privacy risk and AI data governance.
Skills & Experience
Required Skills and Experience:
- 4–8 years of experience in third-party risk management, cyber risk, or information security consulting.
- Proven experience executing end-to-end Third-Party Security Assessments across diverse vendor types (cloud, IT, operational).
- In-depth knowledge of TPRM frameworks including NIST SP 800-161, ISO 27036, and sector-specific regulatory requirements.
- Strong understanding of supply chain risk management including vendor tiering, concentration risk, and dependency mapping.
- Use of AI in TPRM processes. Like using AI for assessor evaluation, writing issue descriptions and risk mitigation plans
- Understanding risk from third parties using AI to provide services to client. Looking into AI governance and AI security
- Understanding risk from third parties using AI Agents to provide services to client. Looking into AI governance and AI security
- Use of AI in TPRM processes. Like using AI Agents to build automations in TPRM processes
- Understanding how things like Frontier AI and Mythos will change cybersecurity Lense and how third parties are protecting themselves from these modern threats
- Experience managing the risk assessment lifecycle including risk identification, rating, mitigation planning, and remediation tracking.
- Ability to conduct control gap analysis against ISO 27001, SOC 2, NIST CSF, CIS Controls, and PCI DSS.
- Experience working with GRC platforms for workflow management and risk tracking.
- Strong analytical, written, and presentation skills for technical and non-technical audiences.
- Hands-on experience with AI-enabled vendor risk scoring tools and external threat intelligence platforms.
- Exposure to predictive modelling techniques applied to vendor risk prioritization and breach likelihood scoring.
- Understanding of AI-driven control monitoring frameworks and machine learning-improved continuous assessment cycles.
- Familiarity with Graph AI concepts for mapping vendor networks and identifying supply chain concentration risks.
- Awareness of NLP-based document analysis tools for automated questionnaire review and evidence validation.
- Experience using data analytics and BI tools (Power BI, Tableau, Python) to build risk dashboards.
- Knowledge of AI governance frameworks and ethical AI risk considerations relevant to vendor AI system assessments.
AI Tools Skillset
Vendor Intelligence & Risk Scoring Platforms:
- BitSight / Security Scorecard / RiskRecon – Active use for real-time vendor cyber ratings, issue tracking, and continuous monitoring feeds.
- Prevalent / ProcessUnity / OneTrust VRM – End-to-end vendor risk assessment workflows, questionnaire management, and risk scoring.
- UpGuard – Vendor surface attack monitoring and data breach detection integrated into TPRM workflows.
AI-Enabled Assessment & Automation Tools:
- Coupa Risk Assess / Ariba Risk – AI-assisted supplier risk evaluation and procurement-integrated due diligence.
- Armorblox / Darktrace – Awareness of AI-driven anomaly detection applicable to vendor environment assessments.
- ChatGPT / Microsoft Copilot for Risk – Drafting risk reports, summarizing vendor evidence, and accelerating assessment documentation.
GRC & Workflow Automation:
- ServiceNow GRC / Archer – Risk workflow management, assessment tracking, and automated risk register maintenance.
- Power Automate / Zapier – Automating vendor questionnaire distribution, evidence collection reminders, and reporting workflows.
Data Analytics & Visualization:
- Microsoft Power BI / Tableau – Building vendor risk dashboards, heat maps, and trend analysis reports.
- Excel Power Query / Python (Pandas) – Risk data cleansing, vendor scoring model inputs, and assessment data aggregation.
Leadership & Behavioral Expectations
- Deliver assigned assessment modules with quality, accuracy, and timeliness.
- Collaborate effectively with cross-functional teams including procurement, legal, IT, and business stakeholders.
- Demonstrate learning agility and proactively expand skills in AI-enabled risk management.
- Support continuous